Biometric Access Control Systems Explained: A Guide for UK Businesses

How Biometric Access Control Works and What Businesses Need to Know

Traditional keys, PIN codes and access cards have long been used to control who can enter commercial premises. However, each relies on something that can potentially be lost, forgotten, shared or stolen.

Biometric access control takes a different approach. Rather than asking someone to present a credential, the system uses a physical or behavioural characteristic to verify their identity.

Fingerprint readers and facial recognition are among the best-known examples, but biometric technology is becoming increasingly sophisticated and accessible for commercial environments. For businesses looking to strengthen site security, manage access more efficiently and create a clearer audit trail, biometrics can provide significant advantages.

However, introducing biometric access control also brings important responsibilities around data protection, system design and how the technology is used.

What is biometric access control?

Biometric access control is a security system that uses an individual’s biological or behavioural characteristics to confirm their identity before granting access to a building, room or restricted area.

Rather than presenting a traditional access card or entering a PIN, an authorised user may scan their fingerprint, look towards a facial recognition reader or use another approved biometric identifier.

The system compares the information captured at the access point with the biometric data enrolled for that individual. Because biometric systems work by assessing similarity rather than expecting two scans to be completely identical, the technology uses predefined matching thresholds to determine whether access should be granted.

What types of biometric access control are available?

There are several forms of biometric authentication that can be used within an access control system.

Fingerprint recognition

Fingerprint access control uses the distinctive characteristics of a person’s fingerprint to verify their identity.

It can be particularly suitable for controlled internal areas where a business wants to remove reliance on cards, fobs or PIN codes.

Facial recognition

Facial recognition systems analyse characteristics of an individual’s face and compare the resulting biometric information with an enrolled template.

Contactless operation can make facial recognition particularly useful in busy commercial environments where authorised users need convenient access without presenting a physical credential.

Iris and retinal recognition

These technologies use characteristics of the eye to verify an individual. They tend to be associated with environments where a particularly high level of identity assurance is required.

Voice and other biometric technologies

Biometric authentication can also incorporate characteristics such as voice, vein patterns and other physiological or behavioural information, although their suitability depends heavily on the environment and application.

The ICO recognises fingerprints, iris scanning, retinal analysis, facial recognition templates and voice among the forms of biometric information organisations may process.

How does a biometric access control system work?

A biometric system normally begins with an enrolment process.

An authorised person’s biometric characteristic is captured and processed to create a biometric template. When that person subsequently attempts to enter a controlled area, a new reading is taken and compared with the enrolled information.

If the system determines that the readings correspond closely enough, access can be authorised.

This process can be integrated with a wider electronic access control system, allowing organisations to establish permissions according to factors such as the individual, location, door or time of day.

For example, general employees might be authorised to enter their normal workspace during designated hours, while access to a server room, plant room or other sensitive area could be restricted to specific personnel.

What are the advantages of biometric access control?

One of the main attractions of biometric access control is that the credential is associated directly with the individual.

An access card can be handed to another person. A PIN can be shared. A key can be copied. A biometric identifier is considerably harder to transfer between users.

This can strengthen confidence that the person requesting access is actually the individual who has been authorised.

Biometric access control can also help businesses:

  • reduce their reliance on physical cards, fobs and keys
  • reduce administration associated with replacing lost credentials
  • create more reliable records of access events
  • introduce stronger controls around sensitive areas
  • combine physical security with more sophisticated access permissions
  • provide convenient access for authorised personnel

For organisations with particularly sensitive locations, biometric authentication can also form part of a multi-factor system. An individual might, for example, require both an access credential and successful biometric verification before entry is permitted.

Where can biometric access control be used?

The appropriate application depends on the individual organisation and the security risk being addressed.

Biometric systems may be considered for areas such as offices, warehouses, manufacturing facilities, healthcare environments, data or communications rooms, laboratories and other restricted locations.

They can also be used selectively rather than across an entire building.

A business may decide that conventional card access remains proportionate for general entrances, while biometric verification is justified for a smaller number of high-security areas.

This risk-based approach is particularly important because biometric access control should not simply be introduced because the technology is available. Businesses should be able to demonstrate why it is appropriate for the particular security requirement.

Biometric access control and UK GDPR

Data protection is one of the most important considerations when implementing biometric access control.

Under UK GDPR, biometric data used for the purpose of uniquely identifying an individual is classed as special category personal data. It therefore receives additional protection under data protection legislation.

This means an organisation cannot simply install a biometric reader and begin enrolling employees.

Businesses need to establish an appropriate lawful basis for processing the personal information and a separate condition allowing them to process special category biometric data. The ICO states that explicit consent may be appropriate in many biometric recognition scenarios, although the correct basis depends on the circumstances and organisations need to assess their own use case.

Where biometrics are being used for workplace access control, the ICO also advises organisations to consider whether an alternative method should be available for workers who do not wish to use biometric access, such as a swipe card or PIN.

Do businesses need a Data Protection Impact Assessment?

A Data Protection Impact Assessment, or DPIA, is an important part of considering biometric access control.

Current ICO guidance states that organisations using a biometric recognition system must complete a DPIA before using the technology. The assessment should consider how biometric information will be processed, the impact on individuals and the measures being introduced to minimise identified risks.

A DPIA can also help an organisation establish whether biometrics are genuinely necessary and proportionate.

Questions worth considering include:

  • What security problem is the system intended to solve?
  • Could the same objective reasonably be achieved with less sensitive information?
  • Who will have access to biometric information?
  • Where will biometric templates be stored?
  • How long will information be retained?
  • What happens when an employee or contractor leaves?
  • What alternative access arrangements will be available where required?
  • What happens if a legitimate user is incorrectly rejected?

These decisions should form part of the security specification rather than being addressed after the system has already been installed.

Are biometric systems completely secure?

No security technology should be regarded as completely infallible.

Biometric systems have advantages, but they also introduce different risks from conventional credentials.

The system needs to distinguish accurately between an authorised individual and somebody who should be refused access. False acceptance and false rejection rates therefore need to be considered when selecting and configuring a system.

The security of stored biometric information is equally important.

Unlike a compromised password or access card, a person’s physical characteristics cannot simply be replaced. Organisations should therefore understand how biometric templates are generated, stored, secured and deleted before choosing a solution.

The National Cyber Security Centre also recommends assessing the security, privacy and performance characteristics of biometric technology rather than assuming all biometric implementations provide the same level of protection.

Biometrics should form part of a wider security strategy

Biometric access control is most effective when it is considered alongside the wider physical security of a site.

Controlling entry through one door provides limited protection if alternative entrances, perimeter weaknesses or internal restricted areas are not considered.

A properly designed solution may therefore combine biometric access control with conventional electronic access control, CCTV, intruder detection, intercom systems and other security measures.

Integration can also improve how security incidents are investigated. Access control records can establish when an authorised credential was used, while CCTV may provide visual context around the same event.

The objective should be to create a proportionate security system in which each technology supports the wider protection of the premises.

Is biometric access control right for your business?

Biometrics can offer a high level of access assurance, but they will not be appropriate for every door or every organisation.

The decision should be based on risk.

For some premises, card-based access control may remain perfectly appropriate. In other environments, particularly where access to sensitive information, equipment or operational areas needs tighter control, biometric authentication may provide an additional level of protection.

Before specifying a system, businesses should consider the areas being protected, the people requiring access, the consequences of unauthorised entry and the data protection obligations created by using biometric information.

Advance Fire & Security can help businesses assess their access control requirements and develop a system suited to the security risks, operational requirements and layout of their premises.

Speak to Advance Fire & Security about upgrading or installing an access control system for your business.